bug#25305: LUKS-encrypted root and unencrypted /boot with GuixSD 0.12.0

2020-11-18 Thread Ludovic Courtès
Hi, Danny Milosavljevic skribis: > (It measures /boot in order to find out whether it has been tampered with or > not) (Off-topic.) I’d be curious to see how much of this approach makes sense in the context of immutable deployments like Guix does. Ludo’.

bug#25305: LUKS-encrypted root and unencrypted /boot with GuixSD 0.12.0

2020-11-18 Thread Danny Milosavljevic
On Mon, 16 Nov 2020 18:56:56 +0100 Jonathan Brielmaier wrote: > We have now pretty good LUKS support, but I don't know if we support > this use case. I always have `/boot` encrypted as well... Unencrypted /boot and encrypted / is necessary to be able to use Heads (right now). (It measures

bug#25305: LUKS-encrypted root and unencrypted /boot with GuixSD 0.12.0

2020-11-16 Thread Jonathan Brielmaier
We have now pretty good LUKS support, but I don't know if we support this use case. I always have `/boot` encrypted as well...

bug#25305: LUKS-encrypted root and unencrypted /boot with GuixSD 0.12.0

2016-12-30 Thread Ludovic Courtès
Hello! Eddie Baxter skribis: > I have attempted to install GuixSD on an encrypted root using LUKS, after > reading the release notes for 0.12.0 that implies this should now work - My > config.scm is linked: > >